Swagshop

13468942

Comments

  • Stuck in 503 many times. 😒
    Please exploit carefully. πŸ˜‚

  • Just ROOTED!!! Finally. For a noob it took me a bit.. Hit me up if you need help!!
    Hints: USER - Enumerate webapp to find a place for the shell
    Root - this thread made me think it was super easy.. I struggled for awhile. Find out what you can do and how to leverage that to get a shell with root privs

  • hi can someone pm me on user on this box, ive found some credz and a login pannel. also tried a number of exploits but nothing...

  • Type your comment> @unashamedgeek said:

    I completed this box. If you need a hint, feel free to message me and include where you are, what you’ve tried, and what you’re thinking is up next and I’ll do my best to nudge you.

    Needed help stuck at admin page for 2 days

  • edited May 14

    Got user via RCE, but can't for the life of me get a reverse shell... I think I know what to do for root, but without that shell I can't execute it.
    Anyone around who can give me a hint?

    EDIT: Got a reverse shell, now for root
    EDIT2: Root done!

    EDIT3: Naturally, you can PM me if you need any help!

  • got root - pm me if you need any help :)

  • Type your comment> @hxmo said:

    Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

    I am getting exactly the same thing today. was working fine yesterday even after resets and no luck today!

  • Type your comment> @Sav said:

    Type your comment> @hxmo said:

    Why the heck cant i use the exploit again to get admin account? worked last night now when i try again it works but it says wrong creds when i try log in?

    I am getting exactly the same thing today. was working fine yesterday even after resets and no luck today!

    yeah mate , i switched from VIP to free server and the free server it worked... wow lol

    but the free server the website keeps getting 503 error paged ALL the time its so frustrating man

    Hack The Box

  • edited May 14

    Hit me up for help with root. Also, for anyone who already got root, pm me if you get a chance. I want to see how you did it, have some questions..

  • Ok, I've encountered alot of error 503s while I've been attempting this box. As I'm a noob could someone explain to me what might cause that error so that I can make sure that I am not part of that problem?

  • i literally can not do a single thing on this box because everytime i find something or get close it gives me a 503 and then i have to wait a couple min before i can even do anything this is so annoying

    if i dont reply add me on discord :) quad#8286

  • Just ridiculous at this point tbh... Its more of a race and who can execute the reverse shell first rather than hack the stupid box man im actually raging, been at this for HOURS man and all i see is 503 loool only had the reverse shell once cos every time after it gets bloody bricked the website.. VIP server doesnt even work on this box lmao

    Hack The Box

  • Same, same-same.
    I'm going to retry under cover of darkness. This very EVENING.

    Naps

  • Pretty fantastic box. Not overly hard but fairly realistic and gave me several "I'm Stupid" moments.

    halligan

  • @hxmo US VIP was very stable. I had shell for the last hour or so with several stupid CTRL+C moments requiring me to re-exploit.

    halligan

  • Got my 20 points for this lovely and frustrating box. Thanks @ch4p for the work <3
    PM me if you need help.

    If I could help you, show some respect: https://www.hackthebox.eu/home/users/profile/98930

  • Got root! Great Box.
    Returning the favor, if anyone needs a tip, feel free to pm.

    @AndreiPintea @NPCMaster Thanks!

    Arrexel

  • i got user but I'm struggling with getting root any hints would be nice

    if i dont reply add me on discord :) quad#8286

  • Rooted! The 503s and 404s has been a tough challenge! This is my 3rd box and learned something from it. As opposed to those people who said that nothing can be learned from this, I can say that this is a good practice for beginners.

    Thanks @ch4p for this box! Thanks @mpzz and @SN01 for the small nudges.

    I am not sure how most of you did it because I can only see MY "special" order to get initial shell. If anyone has time to spare, I'd like to compare my steps to yours.

    PM me if anyone needs a little push to the right direction.

  • is anyone getting the following error with one of their exploits today?

    tunnel = tunnel.group(1)
    AttributeError: 'NoneType' object has no attribute 'group'

    It was working fine for me yesterday and I changed the parameter accordingly, PM me

  • Type your comment> @sornram9254 said:

    Stuck in 503 many times. 😒
    Please exploit carefully. πŸ˜‚

    I've come to find that's actually supposed to happen ;)

  • @UIDEQUALSZERO said:
    is anyone getting the following error with one of their exploits today?

    tunnel = tunnel.group(1)
    AttributeError: 'NoneType' object has no attribute 'group'

    It was working fine for me yesterday and I changed the parameter accordingly, PM me

    The only exploit i used didn't require a lot of change, maybe like a few chars. But to answer the question nah i just tried it again and it worked. Might be the wrong version if it's the exploit i'm thinking of

  • got root and thanks for those who helped me...pm for hint...

  • My first root!!! thanks @marine

  • ROOTED !!

    Thanks @marine for the help..
    PM me for hints..

  • Type your comment> @Tepidangler said:

    Type your comment> @sornram9254 said:

    Stuck in 503 many times. 😒
    Please exploit carefully. πŸ˜‚

    I've come to find that's actually supposed to happen ;)

    This is misleading, you can root this box without causing a 503.

    mogyub

  • Type your comment> @UIDEQUALSZERO said:

    is anyone getting the following error with one of their exploits today?

    tunnel = tunnel.group(1)
    AttributeError: 'NoneType' object has no attribute 'group'

    It was working fine for me yesterday and I changed the parameter accordingly, PM me

    Same here bro!

  • This is my first box. I proceeded to some enumeration regarding ports/services and started tinkering with the website. Found a couple of folders/files which seem interesting but I'm basically stuck. If anyone can PM me with some hints it'd be really appreciated.
  • edited May 15

    I'm having issues finding where I should upload my shell, I see that I can upload M*****o extensions in the downloader page but I'm missing a piece of the puzzle. Could someone PM me a hint?

    Edit: rooted. PM me if you need a nudge. @ch4p the service unavailable errors were a pain but imo it demonstrates why knowing what your exploits do is crucial. Overall a fantastic box!

    DF4U1T

  • Finally rooted ! Thanks a lot @azasdf74M for all the help ..and thanks @ch4p for the box..

Sign In to comment.